CVE-2025-30347: High severity Varnish Enterprise vulnerability
Published Mar 21, 2025
·Updated
Varnish Enterprise before 6.0.13r13 allows remote attackers to obtain sensitive information via an out-of-bounds read for range requests on ephemeral MSE4 stevedore objects.
Affected Software
12 affected components
Varnish Enterprise<6.0.13r13
Varnish-software Varnish Enterprise=6.0.13-r10
Varnish-software Varnish Enterprise=6.0.13-r11
Varnish-software Varnish Enterprise=6.0.13-r12
Varnish-software Varnish Enterprise=6.0.13-r2
Varnish-software Varnish Enterprise=6.0.13-r3
Varnish-software Varnish Enterprise=6.0.13-r4
Varnish-software Varnish Enterprise=6.0.13-r5
Varnish-software Varnish Enterprise=6.0.13-r6
Varnish-software Varnish Enterprise=6.0.13-r7
Varnish-software Varnish Enterprise=6.0.13-r8
Varnish-software Varnish Enterprise=6.0.13-r9
Event History
Mar 21, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30347?
CVE-2025-30347 is classified as a medium-severity vulnerability due to potential data exposure.
2
How do I fix CVE-2025-30347?
To fix CVE-2025-30347, upgrade Varnish Enterprise to version 6.0.13r13 or later.
3
What systems are affected by CVE-2025-30347?
CVE-2025-30347 affects Varnish Enterprise versions prior to 6.0.13r13.
4
What type of vulnerability is CVE-2025-30347?
CVE-2025-30347 is an out-of-bounds read vulnerability that can allow sensitive information to be accessed.
5
Can CVE-2025-30347 be exploited remotely?
Yes, CVE-2025-30347 can be exploited remotely, allowing attackers to obtain sensitive information.